Strong authentication
PBKDF2 password hashing, configurable password policies, TOTP two-factor authentication and controlled session inactivity windows.
HRlume combines modern access controls with Cloudflare-native infrastructure and an option for a fully dedicated deployment.
Security is part of the product, not a separate premium tier.
PBKDF2 password hashing, configurable password policies, TOTP two-factor authentication and controlled session inactivity windows.
Optional Google or Microsoft single sign-on for existing, verified employee accounts. Password sign-in remains available as a recovery path.
Fixed roles and granular custom permissions keep sensitive HR actions restricted to the people who need them.
Audit history covers sensitive administrative and performance actions, creating a clearer record of what changed.
API keys are limited to the supported read-only employee, department and team scopes rather than becoming general-purpose sessions.
Documents are streamed through authenticated application routes instead of being exposed through a public storage bucket.
The application runs as a Cloudflare Worker, stores structured data in D1 and keeps uploaded files in R2. There are no always-on application servers to patch or maintain.
For organisations that require stronger infrastructure isolation, HRlume can provision a complete application instance inside the customer's own Cloudflare account.
Your Cloudflare accountScoped provisioning access
Dedicated HRlume stackWorker · D1 · R2
Your HR workspaceIsolated and licensed
Tell us about your identity, access, deployment and data-isolation needs.